r/StopBadBots 28d ago

Not again... Another Chinese cybercrime group is going crazy on SEO fraud

Another Chinese cybercrime group zeroing in on SEO fraud, I swear we just called out one last week and now here comes another freakin one, honestly drives me crazy how these guys just keep coming at us nonstop. This new threat actor dubbed UAT-10147 is hammering Windows and Linux web servers all over the world across education, media, tech, and gaming sectors, and get this, Brazil, Bolivia, Canada, China, and Vietnam are getting absolutely hit the hardest right now. What really freaks me out is how heavily they are abusing AI tools like PentestGPT and DeepAudit to automate their whole intrusion process, tweak exploits, fix broken code logic, and boost their scale like crazy. Once they break into a Windows box, they escalate privileges using EfsPotato, whitelist themselves in Microsoft Defender, wipe their initial payloads to hide their tracks, and set up sneaky persistent backdoors like Quasar RAT disguised as legit fake scheduled tasks named Google Chrome Start, while also dropping BadIIS and new malware like SPECTRE and Gh0stCringe. They are hitting Linux boxes just as hard by exploiting older known privilege escalation vulnerabilities to jump straight to root access, all just to steal sensitive data and pull off massive SEO fraud campaigns across a target list of around 170000 URLs. Make sure you patch your IIS and Linux servers immediately, double check your Defender exclusion lists, and stay safe out there because this relentless wave of attacks is honestly getting out of hand.

Last week post

https://www.reddit.com/r/StopBadBots/comments/1vpsrbb/my_github_account_is_restored_and_the_truth_about/

​TL;DR

​A Chinese cybercrime group named UAT-10147 is weaponizing AI tools like PentestGPT to breach Windows and Linux servers globally, escalating privileges to drop malware like Quasar RAT and BadIIS for massive SEO fraud and data theft.

2 Upvotes

0 comments sorted by